Guide · Featured · Start here
A practical, source-led guide to building an operationally ready programme for the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.
For boards and executive teams, Data Protection Officers, legal and privacy, CISOs, CTOs, product, data, HR, procurement and internal audit. Last reviewed: 10 August 2026.
This is an implementation guide, not legal advice. Validate the applicable commencement notification, Government directions, Data Protection Board guidance, sectoral obligations and your factual use case with counsel. The Rules were notified in November 2025 with phased commencement. Use May 2027 as the broad operational-readiness target, but do not wait until then to build and test controls.
A credible DPDP programme for 2027 produces five things: a complete inventory of personal data and its flows; valid consent or documented legitimate-use grounds with purpose-specific notices; tested workflows for rights, grievance, withdrawal, retention and breach response; security and vendor controls across the whole processing chain; and inspectable evidence. Accountability sits with the Data Fiduciary, the entity that decides the purpose and means of processing, even when a processor does the work.
DPDP is not a policy-update project. It is an operating-model programme for every organisation that processes digital personal data in India, or processes such data outside India in connection with offering goods or services to people in India. Its practical question is simple: can you explain, control, secure, correct, erase and evidence every important use of personal data?
A credible 2027 programme produces five outcomes.
A full map of digital personal data, purposes, systems, recipients, processors, transfers and retention.
Purpose-specific notices and working consent operations, or a documented legitimate-use analysis where the Act permits it.
Working processes for rights, grievance redressal, withdrawal, retention and erasure, and breach response.
Security and vendor controls that hold across the full processing chain, not only inside your own perimeter.
Records that executives, auditors, customers and the Data Protection Board can inspect on demand.
The core legal responsibility rests with the Data Fiduciary: the person that decides the purpose and means of processing. A Data Processor may carry out processing, but that does not remove the Data Fiduciary's accountability for compliance.
What the Act covers. Sections 2 and 3 define the terms and application. The Act covers digital personal data processed within India where it is collected digitally, or collected non-digitally and then digitised. It also reaches certain processing outside India when connected with offering goods or services to Data Principals in India. It does not apply to personal data made publicly available by the Data Principal, or by another person under a legal obligation to make it public, nor to data processed by an individual for purely personal or domestic purposes.
What to do
The duties in Sections 4 to 8 cannot be met reliably if you do not know what you process, why, where it goes and when it must stop. A website privacy policy is not a data inventory.
Create a processing inventory for every meaningful data flow: customer, prospect, employee, applicant, contractor, supplier-contact, user-generated, support, analytics, telemetry and incident data. For each activity, record the Data Principal group and source; the personal-data categories and business context; the purpose and process owner; the consent or specific legitimate-use basis; the collection channel and notice version; the systems, repositories, logs, warehouses and backups; internal recipients, processors and sub-processors; cross-border destinations; the retention event, duration, deletion method and legal-hold exceptions; and the security classification and key controls.
Map unstructured repositories too: shared drives, chat, email, call recordings, support tickets, documents, code repositories and AI tools. Reconcile the result against application inventories, cloud accounts, procurement and vendor lists, and data-discovery scans.
Control checklist
Under Section 4, personal data may be processed only for a lawful purpose and only with the Data Principal's consent or for certain legitimate uses. Section 5 requires notice, Section 6 sets the standard for consent, and Section 7 lists the specific legitimate uses.
Generate this notice now
Turn Sections 5 and 6 into a plain-language consent notice you can copy or download, then adapt it to your processing.
Open the consent generatorFor a full operating model, see the DPDP Consent Management guide, and for the detailed legal test see the Valid Consent Under Section 6 guide.
Do not import a broad GDPR-style legitimate-interests concept. DPDP instead provides a defined list of legitimate uses, such as voluntary provision of data for a specified purpose, State functions, compliance with law, court or tribunal orders, medical emergencies, disasters, public-health and safety situations, employment-related purposes, and safeguarding employers from loss or liability. Each use needs documented facts and a narrow purpose.
Notice is the first operational control. Before seeking consent, provide a clear, standalone notice. Under the Rules, notices must be comprehensible and itemised. They should state the personal data and purpose, how consent may be withdrawn, the grievance-redressal route, and how to complain to the Board, in English or a language listed in the Eighth Schedule that the Data Principal can access. Avoid a single all-purpose policy; design notices for actual journeys such as signup, employee onboarding, app permissions, lead forms, loyalty programmes, support and partner channels.
Consent is a system, not a checkbox. It must be free, specific, informed, unconditional, unambiguous and signified by clear affirmative action, and it must be as easy to withdraw as to give. Build a consent ledger that stores the notice version, purpose, channel, timestamp, identity reference, affirmative action and withdrawal status, and connect it to CRM, marketing, analytics, product databases, support platforms and processors so that withdrawal changes downstream behaviour.
Control checklist
Section 8 is the operational centre of the Act. It requires a Data Fiduciary to ensure completeness, accuracy and consistency where data is likely to be used for a decision affecting a Data Principal or disclosed to another fiduciary; to implement reasonable security safeguards; to notify breaches; to erase data when consent is withdrawn or the purpose is no longer served, unless retention is required by law; to publish business contact information; and to run effective grievance redressal. It also makes the fiduciary accountable for processing carried out by a processor on its behalf.
Convert it into operating controls
Sections 11 to 15 grant Data Principals the right to a summary of their personal data and processing, the identities of fiduciaries and processors with whom data was shared, correction, completion, updating and erasure, grievance redressal, and the right to nominate another person to exercise rights in case of death or incapacity. Data Principals also have duties, including not impersonating another person or suppressing material information. The Rules require Data Fiduciaries to respond to rights requests within 90 days. This is a service-management and data-architecture challenge, not only a legal one.
Minimum workflow
A child is an individual under 18. Before processing a child's personal data, a Data Fiduciary must obtain verifiable consent of the parent or lawful guardian, subject to notified exemptions, and must not undertake tracking, behavioural monitoring, or targeted advertising directed at children unless a notified exemption applies. Related guardian-verification requirements apply for certain persons with disabilities. This reaches well beyond edtech and gaming: consumer apps, retail, social products, healthcare, family accounts, advertising, workplace benefits and device ecosystems can all encounter children's data.
What to do
The Act requires reasonable security safeguards to prevent personal-data breaches. The Rules describe measures including encryption, obfuscation, masking or virtual tokens; access controls; logging and monitoring; backups; and a minimum one-year retention for certain logs, traffic data and processing-related information. Controls must be risk based and appropriate to your systems and data.
A personal-data breach includes unauthorised processing, accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access that compromises confidentiality, integrity or availability. Affected Data Principals must be informed without delay, and the detailed intimation to the Board is due within 72 hours of becoming aware, unless the Board permits otherwise.
Control checklist
Data must be erased when consent is withdrawn or the specified purpose is no longer being served, unless retention is necessary for compliance with law. The Rules add inactivity-based erasure requirements for certain classes in the Third Schedule, with an advance notice of at least 48 hours. Reconcile this with statutory recordkeeping, fraud, tax, employment, clinical, safety, litigation-hold and security-log requirements.
Processors. The fiduciary remains accountable for processor activity. Maintain a processor and sub-processor register and require written instructions, confidentiality, security, sub-processing controls, prompt breach escalation, rights support, retention and deletion, cooperation and audit, and end-of-contract data return or destruction.
Cross-border transfer (Section 16). Transfers are permitted except to countries or territories restricted by the Central Government, or subject to future Government restrictions for specified data. Maintain a transfer register and monitor notifications. Do not assume that foreign-hosting arrangements are automatically acceptable indefinitely.
The Central Government may notify an organisation or class as a Significant Data Fiduciary, considering the volume and sensitivity of personal data, risk to rights, and potential effects on electoral democracy, the security of the State and public order. An SDF has additional duties: appoint a DPO based in India who reports to the board or governing body, appoint an independent data auditor, run periodic DPIAs and audits, and perform prescribed due diligence for algorithmic software. Large consumer platforms, high-volume processors, organisations using consequential automated decisioning, and entities in sensitive ecosystems should build SDF-ready foundations now.
Section 17 contains exemptions for specified processing, including some State, legal, judicial, research, archival and statistical activities. Exemptions are purpose- and condition-specific: record the exact legal basis and do not treat them as a blanket privacy waiver.
The Data Protection Board of India can inquire into breaches, non-compliance and complaints, direct urgent remedial or mitigation measures, impose financial penalties and accept voluntary undertakings. Appeals go to the Appellate Tribunal (TDSAT). Under the Schedule, failure to maintain reasonable security safeguards can attract a penalty up to Rs 250 crore; breach-notification failures and certain children's-data contraventions can each attract up to Rs 200 crore; and other Data Fiduciary contraventions can attract up to Rs 50 crore.
Review discipline. This guide carries a Last reviewed date. It is updated after any Gazette notification, MeitY or Board direction, court decision or sectoral rule that changes application, timelines, transfers, exemptions or enforcement.
Related
Start by checking where you stand, then get matched with an implementation partner who can own the delivery.